<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Generate cookie vs Accept cookie in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/537763#M110438</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone explain what&amp;nbsp;Generate cookie and Accept cookie actually do? I always find myself messing with the cookie settings when enabling DUO/Azure SAML MFA but confused as to what the difference is and what they do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Schneur_Feldman_0-1680710262228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49285i5BA0286D1108A2CF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Schneur_Feldman_0-1680710262228.png" alt="Schneur_Feldman_0-1680710262228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2023 15:57:48 GMT</pubDate>
    <dc:creator>Schneur_Feldman</dc:creator>
    <dc:date>2023-04-05T15:57:48Z</dc:date>
    <item>
      <title>Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/537763#M110438</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone explain what&amp;nbsp;Generate cookie and Accept cookie actually do? I always find myself messing with the cookie settings when enabling DUO/Azure SAML MFA but confused as to what the difference is and what they do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Schneur_Feldman_0-1680710262228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49285i5BA0286D1108A2CF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Schneur_Feldman_0-1680710262228.png" alt="Schneur_Feldman_0-1680710262228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:57:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/537763#M110438</guid>
      <dc:creator>Schneur_Feldman</dc:creator>
      <dc:date>2023-04-05T15:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/537771#M110441</link>
      <description>&lt;P&gt;GP Agent first connects to portal to pull down list of gateways.&lt;/P&gt;
&lt;P&gt;Then it will connect to one of gateways (either based on priority or latency but this is different topic).&lt;/P&gt;
&lt;P&gt;GP Agent will cache list of gateways. By default for 24 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So every 24 hours GP Agent needs to connect to Portal to check if config has changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This causes user to accept DUO push for portal login and then right after second time for gateway login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To overcome this you can configure portal to generate cookie and gateway to accept cookie with 1 minute timeout.&lt;/P&gt;
&lt;P&gt;This means that if config has timed out in GP Agent and it connects to portal first portal will generate cookie and during second auth to gateway this cookie is used to authenticate instead of full SAML MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If 1 minute passes, user disconnects and connect again then gateway don't accept any more this old cookie and SAML will be used with full blown 2FA auth.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 17:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/537771#M110441</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-05T17:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538155#M110517</link>
      <description>&lt;P&gt;So essentially if you want clients to only get one MFA push then the portal needs to generate a cookie and the gateway needs to be set to accept that cookie? This way the client is getting a push for the portal and gateway?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 17:51:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538155#M110517</guid>
      <dc:creator>Schneur_Feldman</dc:creator>
      <dc:date>2023-04-10T17:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538254#M110533</link>
      <description>&lt;P&gt;If portal generates cookie and gateway accepts cookie then there will be 1 push only - from portal.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:51:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538254#M110533</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-11T14:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538782#M110580</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;Why is there even an option for the gateway client to generate cookies?&amp;nbsp; Does that ever happen and how does it affect which profile is chosen?&amp;nbsp; How can I see this behavior?&amp;nbsp; Could you show an example?&amp;nbsp; Maybe from the client logs?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 13:56:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/538782#M110580</guid>
      <dc:creator>JonGross</dc:creator>
      <dc:date>2023-04-14T13:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Generate cookie vs Accept cookie</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/559863#M113523</link>
      <description>&lt;P&gt;Main reason to use cookie is to avoid sending multiple 2FA requests to user.&lt;/P&gt;
&lt;P&gt;In some cases you don't want to enable 2FA on the portal but on gateway only.&lt;/P&gt;
&lt;P&gt;For example you use LDAP auth on portal and 2FA auth on gateway.&lt;/P&gt;
&lt;P&gt;In this case you want to generate and accept 2FA on gateway only.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:37:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generate-cookie-vs-accept-cookie/m-p/559863#M113523</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-28T13:37:50Z</dc:date>
    </item>
  </channel>
</rss>

